How to permit the ISIS packet in ASA ?

Answered Question
Sep 16th, 2008

The ethertype of the ISIS is 0x83,Does the ASA support this type?how to let the hello or traffic pass the firewall in transperent mode?

thanks

Correct Answer by suschoud about 8 years 5 months ago

Hi,



The transparent mode security appliance does not pass CDP packets or IPv6 packets, or any packets that do not have a valid EtherType greater than or equal to 0x600. For example, you cannot pass IS-IS packets. An exception is made for BPDUs, which are supported.




Reference :



http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/fwmode.html#wp1198794




Please rate if helps.



Regards,

Sushil

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (2 ratings)
Loading.
Correct Answer
suschoud Wed, 09/17/2008 - 04:47

Hi,



The transparent mode security appliance does not pass CDP packets or IPv6 packets, or any packets that do not have a valid EtherType greater than or equal to 0x600. For example, you cannot pass IS-IS packets. An exception is made for BPDUs, which are supported.




Reference :



http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/fwmode.html#wp1198794




Please rate if helps.



Regards,

Sushil

Actions

This Discussion